←back to thread

1318 points xvector | 1 comments | | HN request time: 0.236s | source
Show context
electrotype ◴[] No.19823914[source]
Newbie question: why can't they just renew the certificate, like in 5 minutes?
replies(2): >>19824027 #>>19824520 #
crehn ◴[] No.19824027[source]
They would have to reissue the intermediate certificate, as well as all dependent certificates.
replies(1): >>19824054 #
1. cjbprime ◴[] No.19824054[source]
And there are often bootstrapping problems where e.g. the push that distributes the new intermediate cert to clients is rejected because of the same expiry issue.